EP2141641A1 - Item tracing with supply chain secrecy using RFID tags and an identity-based encryption scheme - Google Patents
Item tracing with supply chain secrecy using RFID tags and an identity-based encryption scheme Download PDFInfo
- Publication number
- EP2141641A1 EP2141641A1 EP09008546A EP09008546A EP2141641A1 EP 2141641 A1 EP2141641 A1 EP 2141641A1 EP 09008546 A EP09008546 A EP 09008546A EP 09008546 A EP09008546 A EP 09008546A EP 2141641 A1 EP2141641 A1 EP 2141641A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- item information
- encrypted
- information
- encryption scheme
- identity
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q10/00—Administration; Management
- G06Q10/06—Resources, workflows, human or project management; Enterprise or organisation planning; Enterprise or organisation modelling
Definitions
- This description relates to item tracing with supply chain secrecy using radio frequency identification (RFID) tags and an identity-based encryption scheme.
- RFID radio frequency identification
- Product tracing may allow the tracing of goods and/or parts across the partially or entirely reconstructed supply chain.
- Product tracing may allow the producer to recall certain batches in case of quality problems or defects that may jeopardize product reliability.
- Product tracing may be an expensive and difficult task, as supply chains may be long and involve several manufacturers/producers and several different materials.
- materials from different batches may contribute to a single batch of a finished product. Thus, when a recall is issued, many suppliers and many batches may be involved.
- Product tracing may be used by different industries. For example, tracing may be used in food products and pharmaceuticals, to enable food product and pharmaceutical recalls if rotten ingredients contaminate certain food batches or pharmaceutical batches. Tracing may be used for quality assurance, for example, in the automotive, aerospace and other industries. Also, laws and regulations have been enacted regarding product traceability. For example, in Europe batch recalls are enforced through European Union (EU) regulation 178/02, and in the United States they are enforced by the Food and Drug Administration (FDA).
- EU European Union
- FDA Food and Drug Administration
- a method for tracing an item may include encrypting item information using an identity-based encryption scheme with a batch number for an item as an encryption key and communicating the encrypted item information for storage on a radio frequency identification (RFID) tag for attachment to the item.
- RFID radio frequency identification
- Implementations may include one or more of the following features.
- the method may further include re-encrypting the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information.
- the encrypted item information may include item recall information.
- the identity-based encryption scheme may include a Boneh-Franklin encryption scheme.
- the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme.
- the RFID tag may include multiple different pieces of encrypted item information and each of the multiple different pieces of encrypted item information may be independently accessible and decryptable.
- the method may further include communicating the batch number to a trusted third party.
- the method also may include generating a decryption key using the batch number.
- the method also may include issuing a recall of the item by generating a decryption key using the batch number and making the decryption key available to users of the item.
- a method for re-encrypting item information may include receiving encrypted item information, re-encrypting the encrypted item information using an identity-based encryption scheme to re-randomize the encrypted item information, and communicating the re-encrypted item information for storage on a radio frequency identification (RFID) tag.
- RFID radio frequency identification
- Implementations may include one or more of the following features.
- the identity-based encryption scheme may include a Boneh-Franklin encryption scheme.
- the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme.
- the method also may include encrypting new item information using the identity-based encryption scheme with a batch number for a new item as an encryption key and communicating the encrypted new item information to the RFID tag.
- the RFID tag may include multiple different pieces of encrypted item information and each of the multiple different pieces of encrypted item information may be independently accessible and decryptable.
- a radio frequency identification (RFID) tag may include a receiver module that is arranged and configured to receive multiple different pieces of encrypted item information and a storage module that is arranged and configured to receive multiple different pieces of encrypted item information and a storage module that is arranged and configured to store the multiple different pieces of encrypted item information, where each of the multiple different pieces of encrypted item information is independently accessible and decryptable.
- RFID radio frequency identification
- Implementations may include one or more of the following features.
- each of the multiple different pieces of encrypted item information may be re-encrypted using an identity-based encryption scheme to re-randomize the pieces of encrypted item information.
- the RFID tag may be a passive RFID tag.
- the RFID tag may be an active RFID tag.
- a computer program product for encrypting item information may be tangibly embodied on a computer-readable medium and include executable code that, when executed, may be configured to cause at least one data processing apparatus to execute an encryption module.
- the encryption module may be configured to encrypt item information using an identity-based encryption scheme with a batch number as an item for an encryption key and communicate the encrypted item information for storage on a radio frequency identification (RFID) tag for attachment to the item.
- RFID radio frequency identification
- Implementations may include one or more of the following features.
- the computer program product may further include executable code that, when executed, may be configured to cause the at least one data apparatus to execute a re-encryption module.
- the re-encryption module may be configured to re-encrypt the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information.
- FIG 1 is an exemplary block diagram of an encryption system.
- FIG 2 is an exemplary block diagram of the encryption system of FIG 1 as included in an enterprise resource system.
- FIG 3 is an exemplary block diagram of the encryption system of FIG 1 as included in an RFID system.
- FIG. 4 is an exemplary block diagram of an RFID tag.
- FIG 5 is an exemplary flowchart of a process that implements the encryption system of FIG 1 .
- FIG 6 is an exemplary flowchart of a process that implements the encryption system of FIG. 1 .
- FIG. 7 is an exemplary block diagram of an example illustration of the encryption system of FIG. 1 .
- FIG 8 is an exemplary block diagram of an example illustration of the encryption system of FIG 1 .
- product tracing may be enabled by using radio frequency identification (RFID) tags that contain encrypted item information.
- RFID radio frequency identification
- the encrypted item information may include product tracing information, item recall information or any other type of information that the producer, distributor or manufacturer would desire to make public, for example, in the event of a product recall.
- the item information may be encrypted using an identity-based encryption scheme.
- Each producer may use their own unique batch number as an encryption key to encrypt the item information using the identity-based encryption scheme.
- each producer would include the encrypted item information about the batch produced and about the products and batches used in the products.
- Each producer would communicate the encrypted item information to an RFID tag and attach the RFID tag to their item.
- the identity-based encryption scheme may include both a private encrypted key (e.g., the batch number) and public cryptographic information, which may be known to participants of the supply chain. However, the encrypted item information may not be revealed with just the public cryptographic information. Both components are needed in order to generate a decryption key to reveal the encrypted item information. In this manner, each producer needs only to maintain a database of their own batch number in order to decrypt the encrypted item information. Each producer may maintain the batch number information themselves or may share it with a trusted third party.
- each producer in the supply chain may re-encrypt the encrypted item information from previous producers using the identity-based encryption scheme to re-randomize the encrypted item information.
- each producer may add their own encrypted item information and store both the encrypted item information and the re-encrypted item information on an RFID tag that is attached to the item.
- each producer may use their own unique batch number as the private encryption key. In this manner, the encryption scheme enables a simple key management since each producer needs only to maintain their batch number or entrust the batch number to the trusted third party.
- Encrypting the item information using an identity-based encryption scheme also enables industrial privacy because as an item proceeds along the supply chain the encrypted information contained on the RFID tag is re-encrypted using the identity-based encryption scheme, which re-randomizes the encrypted item information.
- Encrypting the item information using an identity-based encryption scheme also enables any producer along the supply chain to recall one of its items without the assistance of a downstream producer or distributor in the supply chain.
- the producer need only to make public a decryption key using their own batch number.
- the producer issuing the recall may provide the batch number to be recalled to the trusted third party, who then would generate the decryption key using the batch number and the public cryptographic information.
- the decryption key would then be made available to all users such that an RFID reader would be able to scan products in the supply chain and would reveal the encrypted recall information if one of those products was decoded using the decryption key. Only products matching the decryption key would reveal their encrypted item information.
- secrecy of item information in the supply chain would be maintained. Without a product recall, no information about the supply chain is available to the reseller or any intermediary production facility.
- RFID tags may further ease recalls, as checks can be done almost anywhere. Checks of products for recalls may be performed by producers along the supply chain as well as end retailers such as a store or an end user even at home using a smart refrigerator (e.g., a refrigerator equipped with an RFID reader).
- a smart refrigerator e.g., a refrigerator equipped with an RFID reader.
- the encryption system 100 may include an encryption module 102, a batch data 104, and a re-encryption module 106.
- the encryption system 100 may be used to encrypt item information regarding a particular batch or ingredient of a product.
- the encryption module 102 may be configured to encrypt item information using an identity-based encryption scheme with a batch number for an item as an encryption key.
- identity-based encryption any string may be used as a key to encrypt.
- the batch number is used as the string by a producer to encrypt the item information.
- the encryption system 100 enables a simple key management because the only information that needs to be maintained by a producer is the batch number information, which the producer is likely to maintain in order to track batches.
- a trusted third party 108 may be used to set up some basic (public) parameters. Then, the key may be any string, for example, a batch number.
- a producer presents the key to the trusted third party and proves that he has the right to obtain the decryption key. Then, the trusted third party issues the decryption key.
- the encryption is randomized, such that a cipher text does not reveal any information.
- the identity-based encryption scheme may include a Boneh-Franklin encryption scheme.
- the Boneh-Franklin encryption scheme is based on pairings and elliptic curves.
- the schemes denote points on an elliptic curve with uppercase letters: P , Q... and numbers in Z P with lowercase letters; r , s ... .
- a pairing such as the Weil pairing, may include special properties.
- the following equation denotes the cryptographic pairing used in the Boneh-Franklin identity-based encryption scheme with e(P , Q) denoting the cryptographic pairing.
- identity ID For encryption with the identity ID , one chooses a random number r .
- H I be a cryptographic hash function that maps identities to points on the elliptic curve. Then, one computes e(H I (ID) , T) r .
- H C be a cryptographic hash function that maps pairs to bit strings of a fixed length. Cipher text or message m is then: rP , H C e ⁇ H I ID , T r ⁇ m
- tH I ID
- rP e ⁇ H I ID
- tP r e ⁇ H I ID
- T r end users hash to decrypt the cipher text.
- the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme.
- the Boneh-Boyen-Goh encryption scheme may support hierarchical identity-based encryption.
- the trusted third party 108 may choose a random a as its private information.
- a producer may choose a random s and set the cipher text to: e ⁇ G 1 ⁇ G 2 s ⁇ M , sG , s ⁇ id H + G 3
- a producer may contact the trusted third party 108 and obtain aG 2 + r ⁇ id H + G 3 , rG
- r is a random number chosen from a trusted third party 108.
- the encrypted item information 112 may be communicated for storage on an RFID tag 110.
- the encrypted item information 112 may be stored on the RFID tag 110, which may be attached to or associated with any item.
- the batch data 104 may be a database of batch numbers and other production information regarding a particular item that is maintained by a particular producer.
- the batch data may be considered sensitive information to the producer as it identifies a particular batch of a product that is used along the supply chain.
- Other producers in the supply chain also may consider batch data from a previous producer sensitive information as they would not want their competitors to be able to identify their suppliers.
- the trusted third party 108 may be the producer himself.
- each producer may be their own trusted third party 108, who would be able to generate a decryption key when the batch number information is provided.
- the trusted third party 108 may be a separate third party entity. There may be more than one trusted third party 108 along a particular supply chain.
- the RFID tag 110 may include multiple different pieces of encrypted item information. Each of the multiple different pieces of encrypted item information 112 may be independently accessible and decryptable. Thus, if a particular RFID tag 110 includes encrypted information from multiple different producers and a recall is issued by only a single producer, then only the recalled batch information would be decrypted. The other encrypted information would maintain its encryption and, thus, its secrecy. If a producer issues a recall and a particular RFID tag 110 does not include any of the batch recall information, then all of the multiple different pieces of encrypted item information 112 on that RFID tag 110 remain encrypted and thus remain secret.
- the re-encryption module 106 may be configured to re-encrypt the encrypted item information 112 using the identity-based encryption scheme to re-randomize the encrypted item information. In this manner, the identity-based encryption scheme may be universally re-encryptable. The re-encryption module 106 may re-encrypt the encrypted item information 112 without knowledge of the batch number used to originally encrypt the item information.
- the Boneh-Franklin (BF) encryption scheme may be universally re-encryptable.
- the message m (which is not necessarily sensitive) may be transmitted in plaintext alongside the partial cipher text.
- the recall information (e.g., messages m ) may be aggregated upstream along the supply chain.
- a recall for example, by supplier/consumer Y , he issues the batch " b " to be recalled along with a proof of identity to the trusted third party 108.
- the trusted third party 108 publishes the private key for Y
- the Boneh-Boyen-Goh (BBG) encryption scheme may be universally re-encryptable.
- BBG Boneh-Boyen-Goh
- the solution for BBG encryption enables hiding the plaintext, such that it may contain sensitive information that should only be revealed in case of a recall, but then cipher texts may not be aggregated upstream the supply chain.
- the result is a cipher text that is a completely indistinguishable cipher text, where the first part is randomized by s + rv and the second part by rw .
- Each company X places a cipher text for its batch with public key "batch number"
- the encryption system 100 is illustrated as part of an enterprise resource planning (ERP) system 200.
- the encryption system 100 may include the encryption module 102, the batch data 104, and the re-encryption module 106.
- the encryption system 100 may be a component or a module of the ERP system 200.
- the encryption system 100 and the ERP system 200 may interface with each other such that the ERP system 200 provides the batch information to be stored in the batch data 104.
- the batch data 104 may store information about the produced batches and private cryptographic information used for encrypting information for each batch.
- the trusted third party 108 may be a part of the system.
- An RFID system 250 may interface with the ERP system 200.
- the RFID system 250 may include the RFID tag 110 and an RFID reader 252.
- the encryption system 100 specifically the encryption module 102, may communicate encrypted item information to the RFID system 250.
- the RFID reader 252 may be configured to communicate the encrypted item information for storage on the RFID tag 110.
- the re-encryption module 106 may be configured to communicate re-encrypted item information to the RFID system 250.
- the RFID reader 252 may be configured to communicate the re-encrypted item information for storage on the RFID tag 110.
- the encryption system 100 may be a part of another system or component.
- the encryption system 100 may be a component or module of the RFID system 250.
- the RFID system 250 encrypts the item information using the batch number provided by the ERP system 200.
- an existing interface between the ERP system 200 and RFID system 250 may be utilized to communicate the batch number information from the batch data 104 to the RFID system 250.
- the batch number may be used by the encryption system 100 to generate the encrypted item information and/or the re-encrypted item information.
- the encryption system 100 may be a component or module of other intermediary systems.
- the encryption system 100 may be a component of an auto identification system that interfaces with both the ERP system 200 and the RFID system 250.
- the auto identification system may generate the encrypted item information and/or the re-encrypted item information using the encryption module 102 and/or the re-encryption module 104, respectively.
- the RFID tag 110 may include a receiver module 402, a storage module 404, an optional power module 406, and an antenna 408.
- the receiver module 402, storage module 404, and power module 406 may be implemented as an integrated circuit (IC).
- the RFID tag 110 may be a passive RFID tag, an active RFID tag, or a semi-passive RFID tag. If the RFID tag is a passive RFID tag, then the power module 406 may not be included as part of the RFID tag. In a passive RFID tag, an RFID reader may provide power to the RFID tag such that the information on the RFID tag may be read using the antenna 408. If the RFID tag is an active RFID tag, then the power module 406 may be included.
- the antenna 408 may be used to transmit and receive information from an RFID reader, such as RFID reader 252 of FIGs.2 and 3 .
- the receiver module 402 may be configured to receive multiple different pieces of encrypted item information, such as encrypted item information 112.
- the storage module 404 may be configured to store the multiple different pieces of encrypted item information 112.
- Each of the different pieces of the different encrypted item information may be independently accessible and decryptable. In this manner, when an RFID reader scans the RFID tag 110, only the encrypted item information that properly matches up with a decryption key will be revealed. All other pieces of encrypted item information will not be revealed and will remain encrypted.
- the encrypted item information 112 may be re-encrypted using one of the identity-based encryption schemes to re-randomize the pieces of encrypted item information.
- the process 500 may include a process for tracing an item.
- Process 500 may include encrypting item information using an identity-based encryption scheme with a batch number for an item as an encryption key (510) and communicating the encrypted item information for storage on an RFID tag for attachment to the item (520).
- the encryption module 102 may be used to encrypt item information using an identity-based encryption scheme with a batch number for an item as an encryption key, where the batch number may be stored in the batch data 104 (510).
- the encrypted item information may include recall information (512).
- the recall information may include instructions to producers, distributor, end consumers, or anyone in the supply chain as to how to handle a recalled item. Instructions may include contact information such as phone number or an address regarding the recalled item or instructions on how to process the recalled item.
- the identity-based encryption scheme may include a Boneh-Franklin scheme (514). In another exemplary implementation, the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme (516).
- Encryption module 102 may be configured to communicate the encrypted item information for storage on an RFID tag 110 for attachment to the item (520).
- the RFID tag 110 may include multiple different pieces of encrypted item information, where each of the multiple different pieces of encrypted item information is independently accessible and decryptable (522).
- Process 500 also may include re-encrypting the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information (530).
- the re-encryption module 106 may be used to re-encrypt the encrypted item information (530). In this manner, as the item information is transmitted along the supply chain, the encrypted item information is re-encrypted so that it is re-randomized.
- the re-encryption module 106 may re-encrypt the item information without knowledge of the encryption key (e.g., the batch number) used to encrypt the item information.
- the batch number may be communicated to a trusted third party 108 (540).
- a decryption key may be generated using the batch number (550).
- the trusted third party 108 may generate the decryption key upon proof from a particular producer that they are entitled to receive the private key using the batch number.
- Process 500 also may include issuing a recall of an item by generating a decryption key using the batch number and making the decryption key available to users of the item (560).
- the decryption key is generated and is made publicly available for producers and end users along the supply chain to scan items and products using an RFID reader and a decryption key to determine whether or not an item has been recalled. Only encrypted item information on the RFID tag that matches the decryption key will be disclosed to the producer or the end user using the RFID reader.
- Process 600 may include receiving encrypted item information (610), re-encrypting the encrypted item information using an identity-based encryption scheme to re-randomize the encrypted item information (620) and communicating the re-encrypted item information for storage on an RFID tag for attachment to the item (630).
- the re-encryption module 106 may be configured to receive the encrypted item information.
- the re-encryption module 106 may be configured to re-encrypt the encrypted item information using one of the identity-based encryption schemes (620).
- the identity-based encryption scheme may include a Boneh-Franklin encryption scheme (622).
- the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme (624).
- the encryption system 100 may communicate the re-encrypted item information for storage on the RFID tag 110.
- the RFID tag 100 may include multiple different pieces of encrypted item information and each of the multiple different pieces of encrypted item information may be independently accessible and decryptable (632).
- the re-encryption module 106 may be configured to re-encrypt to encrypted item information without knowledge of the encryption key (e.g., batch number) used to encrypt the item information.
- Process 600 also may include encrypting new item information using the identity-based encryption scheme with a batch number for a new item as an encryption key in communicating the encrypted new item information to the RFID tag (640).
- the encryption module 102 may encrypt new item information using the identity-based encryption scheme with a batch number from the batch data 104 for the new item as the encryption key.
- the encryption module 102 may communicate the encrypted new item information to the RFID tag 110.
- producers along the supply chain may provide their own encrypted item information as well as re-encrypting item information received from previous producers in the supply chain. That way the information from previous producers is re-randomized such that supply chain secrecy is maintained throughout the supply chain.
- Producer X 702 may sell grain.
- the grain may be shipped in different batches such as batch a1704, batch a2 706, and batch a3 708.
- Producer Y 710 may buy grain from Producer X 702 and make flour out of it.
- Producer Y 710 also makes different batches of flour such as batch b1 712, batch b2 714, and batch b3 716.
- the different batches from Producer X 702 may contribute to a single batch of flour produced by Producer Y 710.
- batch a3 708 is used to produce batch b3 716.
- batch a2 706 is used by Producer Y 710 to produce both batch b1 712 and batch b2 714.
- batch a1 704 is used to produce batch b1 712.
- Producer Z 718 uses the flour from Producer Y 710 to bake bread. Just as Producer X 702 and Producer Y 710 made different batches, so too does Producer Z 718 make multiple batches. For example, Producer Z 718 may produce multiple batches of bread including batch c1 720, batch c2 722, and batch c3 724.
- each of the producers may trace each of the separate batches using encrypted item information that is stored on an RFID tag.
- each of the producers may use an ERP system such as the ERP system 200 of FIG 2 .
- the batch data 104 may store information about the produced batches and private cryptographic information used for encrypting information for each batch.
- each of the producers may attach RFID tags 110a, 110b and 110c to their goods.
- the RFID tags 110a, 110b and 110c may contain item information 112a, 112b, and 112c.
- the item information 112a, 112b, and 112c may be encrypted using an identity-based encryption scheme.
- the producer will include encrypted item information about the batch that producer produced, and about the products and batches used in his product.
- Producer X 702 produces a good such as wheat.
- information about the batch of the goods is encrypted using an identity-based encryption scheme.
- the encrypted item information is written to an RFID tag 880 and sent to Producer Y 710.
- Producer X 702 may store the information about the batch and the private cryptographic information in the batch data 104 of the encryption system 100 of his ERP system 200.
- Producer Y 710 may produce a good using different batches from Producer X 702. Each batch produced by Producer Y 710 may contain encrypted item information about the batch of the good. Producer Y 710 may use the encryption system 100 to encrypt the item information about the good produced by Producer Y 710 and to write the information to an RFID tag 885 that is sent along with the goods to Producer Z 718.
- the RFID tag 885 may include the encrypted item information about the batches from Producer Y 710 and also include the re-encrypted item information which has been re-randomized about the batches and encrypted item information that was received from Producer X 702. Producer Y 710 may store this information in the batch data 104 of his encryption system 100.
- FIG. 8 illustrates a simple example in which each batch only contains products from one other batch
- FIG. 7 illustrates more complex examples in which materials from different batches may contribute to a single batch.
- each of the different pieces of encrypted item information that is used to produce a single batch is re-encrypted using the re-encryption module 106.
- Producer Z 718 may produce a good and fit it with an RFID tag 890 containing encrypted information similar to step 2.
- the finished product may be shipped to a retailer that will offer the product to customers.
- the finished product may contain the single RFID tag 890 which includes the encrypted item information regarding each of the batches from each of the different producers that was used to produce the finished product.
- step 5 Producer Y 710 produced one batch of rotten goods. The goods were already processed by Producer Z 718 and shipped to a retailer. To enable recalling of the affected products, Producer Y 710 may reveal the private cryptographic information about the rotten batch to a trusted third party 108. In step 6, the trusted third party 108 may publish this information to all retailers. The retailers can use this information to find the affected products and remove them from their shelves.
- the examples provided illustrate encrypted item information being stored on RFID tags, other techniques might be used such as, for example, barcodes, two dimensional barcodes or holograms.
- the encrypted item information may be sent in advance, for example, using messages over a computer network.
- the encrypted item information may be sent on demand, for example, using messages over a computer network.
- the encrypted item information might be exchanged using emails, web services, or remote procedure calls (RPC).
- Implementations of the various techniques described herein may be implemented in digital electronic circuitry, or in computer hardware, firmware, software, or in combinations of them. Implementations may be implemented as a computer program product, i.e., a computer program tangibly embodied in an information carrier, e.g., in a machine-readable storage device or in a propagated signal, for execution by, or to control the operation of, data processing apparatus, e.g., a programmable processor, a computer, or multiple computers.
- data processing apparatus e.g., a programmable processor, a computer, or multiple computers.
- a computer program such as the computer program(s) described above, can be written in any form of programming language, including compiled or interpreted languages, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.
- a computer program can be deployed to be executed on one computer or on multiple computers at one site or distributed across multiple sites and interconnected by a communication network.
- Method steps may be performed by one or more programmable processors executing a computer program to perform functions by operating on input data and generating output. Method steps also may be performed by, and an apparatus may be implemented as, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit).
- FPGA field programmable gate array
- ASIC application-specific integrated circuit
- processors suitable for the execution of a computer program include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer.
- a processor will receive instructions and data from a read-only memory or a random access memory or both.
- Elements of a computer may include at least one processor for executing instructions and one or more memory devices for storing instructions and data.
- a computer also may include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto-optical disks, or optical disks.
- Information carriers suitable for embodying computer program instructions and data include all forms of non-volatile memory, including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks, e.g., internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks.
- semiconductor memory devices e.g., EPROM, EEPROM, and flash memory devices
- magnetic disks e.g., internal hard disks or removable disks
- magneto-optical disks e.g., CD-ROM and DVD-ROM disks.
- the processor and the memory may be supplemented by, or incorporated in special purpose logic circuitry.
- implementations may be implemented on a computer having a display device, e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor, for displaying information to the user and a keyboard and a pointing device, e.g., a mouse or a trackball, by which the user can provide input to the computer.
- a display device e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor
- keyboard and a pointing device e.g., a mouse or a trackball
- Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including acoustic, speech, or tactile input.
- Implementations may be implemented in a computing system that includes a back-end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front-end component, e.g., a client computer having a graphical user interface or a Web browser through which a user can interact with an implementation, or any combination of such back-end, middleware, or front-end components.
- Components may be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN) and a wide area network (WAN), e.g., the Internet.
- LAN local area network
- WAN wide area network
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Human Resources & Organizations (AREA)
- Strategic Management (AREA)
- Economics (AREA)
- Entrepreneurship & Innovation (AREA)
- Educational Administration (AREA)
- Game Theory and Decision Science (AREA)
- Development Economics (AREA)
- Marketing (AREA)
- Operations Research (AREA)
- Quality & Reliability (AREA)
- Tourism & Hospitality (AREA)
- Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- General Physics & Mathematics (AREA)
- Theoretical Computer Science (AREA)
- Storage Device Security (AREA)
Abstract
A method for tracing an item may include encrypting item information using an identity-based encryption scheme with a batch number for an item as an encryption key and communicating the encrypted item information for storage on a radio frequency identification (RFID) tag for attachment to the item.
Description
- This description relates to item tracing with supply chain secrecy using radio frequency identification (RFID) tags and an identity-based encryption scheme.
- Product tracing may allow the tracing of goods and/or parts across the partially or entirely reconstructed supply chain. Product tracing may allow the producer to recall certain batches in case of quality problems or defects that may jeopardize product reliability. Product tracing may be an expensive and difficult task, as supply chains may be long and involve several manufacturers/producers and several different materials. Furthermore, materials from different batches may contribute to a single batch of a finished product. Thus, when a recall is issued, many suppliers and many batches may be involved.
- Product tracing may be used by different industries. For example, tracing may be used in food products and pharmaceuticals, to enable food product and pharmaceutical recalls if rotten ingredients contaminate certain food batches or pharmaceutical batches. Tracing may be used for quality assurance, for example, in the automotive, aerospace and other industries. Also, laws and regulations have been enacted regarding product traceability. For example, in Europe batch recalls are enforced through European Union (EU) regulation 178/02, and in the United States they are enforced by the Food and Drug Administration (FDA).
- Current product tracing solutions may not enable the supply chain privacy desired by producers and manufacturers. The public availability of product tracing information may allow competitors or even collaborators to inspect a producer's supply chain and make an assessment of the producer's logistics or product capabilities, even without any recalls having been issued. Some product tracing solutions may slowly react to product recalls due to an enormous communications overhead. Consequently, producers may desire a solution that enables supply chain secrecy to protect supply chain logistics and product capabilities. Suppliers also may desire a solution that enables faster product recalls without an enormous communications overhead.
- According to one general aspect, a method for tracing an item may include encrypting item information using an identity-based encryption scheme with a batch number for an item as an encryption key and communicating the encrypted item information for storage on a radio frequency identification (RFID) tag for attachment to the item.
- Implementations may include one or more of the following features. For example, the method may further include re-encrypting the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information. The encrypted item information may include item recall information. In one exemplary implementation, the identity-based encryption scheme may include a Boneh-Franklin encryption scheme. In another exemplary implementation, the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme.
- The RFID tag may include multiple different pieces of encrypted item information and each of the multiple different pieces of encrypted item information may be independently accessible and decryptable. The method may further include communicating the batch number to a trusted third party. The method also may include generating a decryption key using the batch number. The method also may include issuing a recall of the item by generating a decryption key using the batch number and making the decryption key available to users of the item.
- In another general aspect, a method for re-encrypting item information may include receiving encrypted item information, re-encrypting the encrypted item information using an identity-based encryption scheme to re-randomize the encrypted item information, and communicating the re-encrypted item information for storage on a radio frequency identification (RFID) tag.
- Implementations may include one or more of the following features. For example, the identity-based encryption scheme may include a Boneh-Franklin encryption scheme. In another exemplary implementation, the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme.
- The method also may include encrypting new item information using the identity-based encryption scheme with a batch number for a new item as an encryption key and communicating the encrypted new item information to the RFID tag. The RFID tag may include multiple different pieces of encrypted item information and each of the multiple different pieces of encrypted item information may be independently accessible and decryptable.
- In another general aspect, a radio frequency identification (RFID) tag may include a receiver module that is arranged and configured to receive multiple different pieces of encrypted item information and a storage module that is arranged and configured to receive multiple different pieces of encrypted item information and a storage module that is arranged and configured to store the multiple different pieces of encrypted item information, where each of the multiple different pieces of encrypted item information is independently accessible and decryptable.
- Implementations may include one or more of the following features. For example, each of the multiple different pieces of encrypted item information may be re-encrypted using an identity-based encryption scheme to re-randomize the pieces of encrypted item information. In one exemplary implementation, the RFID tag may be a passive RFID tag. In another exemplary implementation, the RFID tag may be an active RFID tag.
- In another general aspect, a computer program product for encrypting item information may be tangibly embodied on a computer-readable medium and include executable code that, when executed, may be configured to cause at least one data processing apparatus to execute an encryption module. The encryption module may be configured to encrypt item information using an identity-based encryption scheme with a batch number as an item for an encryption key and communicate the encrypted item information for storage on a radio frequency identification (RFID) tag for attachment to the item.
- Implementations may include one or more of the following features. For example, the computer program product may further include executable code that, when executed, may be configured to cause the at least one data apparatus to execute a re-encryption module. The re-encryption module may be configured to re-encrypt the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information.
- The details of one or more implementations are set forth in the accompanying drawings and the description below. Other features will be apparent from the description and drawings, and from the claims.
-
FIG 1 is an exemplary block diagram of an encryption system. -
FIG 2 is an exemplary block diagram of the encryption system ofFIG 1 as included in an enterprise resource system. -
FIG 3 is an exemplary block diagram of the encryption system ofFIG 1 as included in an RFID system. -
FIG. 4 is an exemplary block diagram of an RFID tag. -
FIG 5 is an exemplary flowchart of a process that implements the encryption system ofFIG 1 . -
FIG 6 is an exemplary flowchart of a process that implements the encryption system ofFIG. 1 . -
FIG. 7 is an exemplary block diagram of an example illustration of the encryption system ofFIG. 1 . -
FIG 8 is an exemplary block diagram of an example illustration of the encryption system ofFIG 1 . - In one exemplary implementation, product tracing may be enabled by using radio frequency identification (RFID) tags that contain encrypted item information. The encrypted item information may include product tracing information, item recall information or any other type of information that the producer, distributor or manufacturer would desire to make public, for example, in the event of a product recall.
- In one exemplary implementation, the item information may be encrypted using an identity-based encryption scheme. Each producer may use their own unique batch number as an encryption key to encrypt the item information using the identity-based encryption scheme. In each part of the supply chain, each producer would include the encrypted item information about the batch produced and about the products and batches used in the products. Each producer would communicate the encrypted item information to an RFID tag and attach the RFID tag to their item.
- The identity-based encryption scheme may include both a private encrypted key (e.g., the batch number) and public cryptographic information, which may be known to participants of the supply chain. However, the encrypted item information may not be revealed with just the public cryptographic information. Both components are needed in order to generate a decryption key to reveal the encrypted item information. In this manner, each producer needs only to maintain a database of their own batch number in order to decrypt the encrypted item information. Each producer may maintain the batch number information themselves or may share it with a trusted third party.
- As an item proceeds along the supply chain, each producer in the supply chain may re-encrypt the encrypted item information from previous producers using the identity-based encryption scheme to re-randomize the encrypted item information. In addition, each producer may add their own encrypted item information and store both the encrypted item information and the re-encrypted item information on an RFID tag that is attached to the item. In one exemplary implementation, each producer may use their own unique batch number as the private encryption key. In this manner, the encryption scheme enables a simple key management since each producer needs only to maintain their batch number or entrust the batch number to the trusted third party.
- Encrypting the item information using an identity-based encryption scheme also enables industrial privacy because as an item proceeds along the supply chain the encrypted information contained on the RFID tag is re-encrypted using the identity-based encryption scheme, which re-randomizes the encrypted item information.
- Encrypting the item information using an identity-based encryption scheme also enables any producer along the supply chain to recall one of its items without the assistance of a downstream producer or distributor in the supply chain. In order for a particular item to be recalled, the producer need only to make public a decryption key using their own batch number. In one implementation, the producer issuing the recall may provide the batch number to be recalled to the trusted third party, who then would generate the decryption key using the batch number and the public cryptographic information. The decryption key would then be made available to all users such that an RFID reader would be able to scan products in the supply chain and would reveal the encrypted recall information if one of those products was decoded using the decryption key. Only products matching the decryption key would reveal their encrypted item information. Thus, secrecy of item information in the supply chain would be maintained. Without a product recall, no information about the supply chain is available to the reseller or any intermediary production facility.
- The use of RFID tags may further ease recalls, as checks can be done almost anywhere. Checks of products for recalls may be performed by producers along the supply chain as well as end retailers such as a store or an end user even at home using a smart refrigerator (e.g., a refrigerator equipped with an RFID reader).
- Referring to
FIG. 1 , anencryption system 100 is illustrated. Theencryption system 100 may include anencryption module 102, abatch data 104, and are-encryption module 106. Theencryption system 100 may be used to encrypt item information regarding a particular batch or ingredient of a product. - The
encryption module 102 may be configured to encrypt item information using an identity-based encryption scheme with a batch number for an item as an encryption key. In identity-based encryption any string may be used as a key to encrypt. In one exemplary implementation, the batch number is used as the string by a producer to encrypt the item information. In this manner, theencryption system 100 enables a simple key management because the only information that needs to be maintained by a producer is the batch number information, which the producer is likely to maintain in order to track batches. In the identity-based encryption scheme, a trustedthird party 108 may be used to set up some basic (public) parameters. Then, the key may be any string, for example, a batch number. To obtain the decryption key, a producer presents the key to the trusted third party and proves that he has the right to obtain the decryption key. Then, the trusted third party issues the decryption key. The encryption is randomized, such that a cipher text does not reveal any information. - In one exemplary implementation, the identity-based encryption scheme may include a Boneh-Franklin encryption scheme. The Boneh-Franklin encryption scheme is based on pairings and elliptic curves. The schemes denote points on an elliptic curve with uppercase letters: P, Q... and numbers in ZP with lowercase letters; r, s... . A pairing such as the Weil pairing, may include special properties. The following equation denotes the cryptographic pairing used in the Boneh-Franklin identity-based encryption scheme with e(P, Q) denoting the cryptographic pairing.
- P and T = tP are the public parameters of the Boneh-Franklin encryption scheme, with t being the private information of the trusted
third party 108. For encryption with the identity ID, one chooses a random number r. Let HI be a cryptographic hash function that maps identities to points on the elliptic curve. Then, one computes e(HI(ID), T)r. Let HC be a cryptographic hash function that maps pairs to bit strings of a fixed length. Cipher text or message m is then: -
- In another exemplary implementation, the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme. The Boneh-Boyen-Goh encryption scheme may support hierarchical identity-based encryption. In this implementation, the trusted
third party 108 may choose a random a as its private information. The trustedthird party 108 publishes (G, G1 = aG, G2, G3, H) as public parameters. In order to encrypt, a producer may choose a random s and set the cipher text to: -
-
- Once a producer has used an
encryption system 100 and theencryption module 102 to encrypt the item information, theencrypted item information 112 may be communicated for storage on anRFID tag 110. Theencrypted item information 112 may be stored on theRFID tag 110, which may be attached to or associated with any item. - The
batch data 104 may be a database of batch numbers and other production information regarding a particular item that is maintained by a particular producer. The batch data may be considered sensitive information to the producer as it identifies a particular batch of a product that is used along the supply chain. Other producers in the supply chain also may consider batch data from a previous producer sensitive information as they would not want their competitors to be able to identify their suppliers. - In one exemplary implementation, the trusted
third party 108 may be the producer himself. For example, each producer may be their own trustedthird party 108, who would be able to generate a decryption key when the batch number information is provided. In another exemplary implementation, the trustedthird party 108 may be a separate third party entity. There may be more than one trustedthird party 108 along a particular supply chain. - In one exemplary implementation, the
RFID tag 110 may include multiple different pieces of encrypted item information. Each of the multiple different pieces ofencrypted item information 112 may be independently accessible and decryptable. Thus, if aparticular RFID tag 110 includes encrypted information from multiple different producers and a recall is issued by only a single producer, then only the recalled batch information would be decrypted. The other encrypted information would maintain its encryption and, thus, its secrecy. If a producer issues a recall and aparticular RFID tag 110 does not include any of the batch recall information, then all of the multiple different pieces ofencrypted item information 112 on thatRFID tag 110 remain encrypted and thus remain secret. - The
re-encryption module 106 may be configured to re-encrypt theencrypted item information 112 using the identity-based encryption scheme to re-randomize the encrypted item information. In this manner, the identity-based encryption scheme may be universally re-encryptable. There-encryption module 106 may re-encrypt theencrypted item information 112 without knowledge of the batch number used to originally encrypt the item information. - In one exemplary implementation, the Boneh-Franklin (BF) encryption scheme may be universally re-encryptable. The cipher text of the BF encryption R=rP, e(H(ID), T)r may be re-randomized by computing r'R, (e(H(ID), T)r)r'. In this implementation, the message m (which is not necessarily sensitive) may be transmitted in plaintext alongside the partial cipher text. As an additional benefit, the recall information (e.g., messages m) may be aggregated upstream along the supply chain.
- For example:
- 1. A producer X has a batch "a" which he intends to ship to Y and Y'. He sends the shipment along with [R=rP, e(H(X|a), T)r, infx] to Y (and Y'), where infX can be any information he wants to reveal in case of a recall. In case there is no such information, it can be a random number.
- 2. Consumer Y is an intermediary. He produces several batches "b" from "a" and ships them to consumer Z. Using the
re-encryption module 106, he re-randomizes the information of X and sends along - 3. Consumer Z produces the final good "c". Using the
re-encryption module 106, he re-randomizes the received information and places anRFID tag 110 on each item with the following information: - In case of a recall, for example, by supplier/consumer Y, he issues the batch "b" to be recalled along with a proof of identity to the trusted
third party 108. The trustedthird party 108 publishes the private key for Y|b to all resellers (or even end-users) which can then scan their entire inventory for recalled goods. No involvement of intermediary supply chain partners, such as Z is necessary in the tracing. Y himself can issue the recall to the resellers/end-users directly increasing the reaction time to market. - In another exemplary implementation, the Boneh-Boyen-Goh (BBG) encryption scheme may be universally re-encryptable. The solution for BBG encryption enables hiding the plaintext, such that it may contain sensitive information that should only be revealed in case of a recall, but then cipher texts may not be aggregated upstream the supply chain.
-
-
- The result is a cipher text that is a completely indistinguishable cipher text, where the first part is randomized by s + rv and the second part by rw. Each company X places a cipher text for its batch with public key "batch number" | X on the
RFID tag 110 or transmits it along the supply chain until it can be stored on the final RFID tag. Such transmission can also occur via RFID tags. - Referring to
FIG. 2 , theencryption system 100 is illustrated as part of an enterprise resource planning (ERP)system 200. Theencryption system 100 may include theencryption module 102, thebatch data 104, and there-encryption module 106. Theencryption system 100 may be a component or a module of theERP system 200. Theencryption system 100 and theERP system 200 may interface with each other such that theERP system 200 provides the batch information to be stored in thebatch data 104. Thus, thebatch data 104 may store information about the produced batches and private cryptographic information used for encrypting information for each batch. The trustedthird party 108 may be a part of the system. - An
RFID system 250 may interface with theERP system 200. TheRFID system 250 may include theRFID tag 110 and anRFID reader 252. Theencryption system 100, specifically theencryption module 102, may communicate encrypted item information to theRFID system 250. TheRFID reader 252 may be configured to communicate the encrypted item information for storage on theRFID tag 110. There-encryption module 106 may be configured to communicate re-encrypted item information to theRFID system 250. TheRFID reader 252 may be configured to communicate the re-encrypted item information for storage on theRFID tag 110. - In another exemplary implementation, the
encryption system 100 may be a part of another system or component. Referring toFIG. 3 , theencryption system 100 may be a component or module of theRFID system 250. In this manner, theRFID system 250 encrypts the item information using the batch number provided by theERP system 200. Thus, an existing interface between theERP system 200 andRFID system 250 may be utilized to communicate the batch number information from thebatch data 104 to theRFID system 250. The batch number may be used by theencryption system 100 to generate the encrypted item information and/or the re-encrypted item information. - In other exemplary implementations, the
encryption system 100 may be a component or module of other intermediary systems. For example, theencryption system 100 may be a component of an auto identification system that interfaces with both theERP system 200 and theRFID system 250. The auto identification system may generate the encrypted item information and/or the re-encrypted item information using theencryption module 102 and/or there-encryption module 104, respectively. - Referring to
FIG. 4 , anexemplary RFID tag 110 is illustrated. TheRFID tag 110 may include areceiver module 402, astorage module 404, anoptional power module 406, and anantenna 408. Thereceiver module 402,storage module 404, andpower module 406 may be implemented as an integrated circuit (IC). - The
RFID tag 110 may be a passive RFID tag, an active RFID tag, or a semi-passive RFID tag. If the RFID tag is a passive RFID tag, then thepower module 406 may not be included as part of the RFID tag. In a passive RFID tag, an RFID reader may provide power to the RFID tag such that the information on the RFID tag may be read using theantenna 408. If the RFID tag is an active RFID tag, then thepower module 406 may be included. Theantenna 408 may be used to transmit and receive information from an RFID reader, such asRFID reader 252 ofFIGs.2 and3 . - The
receiver module 402 may be configured to receive multiple different pieces of encrypted item information, such asencrypted item information 112. Thestorage module 404 may be configured to store the multiple different pieces ofencrypted item information 112. Each of the different pieces of the different encrypted item information may be independently accessible and decryptable. In this manner, when an RFID reader scans theRFID tag 110, only the encrypted item information that properly matches up with a decryption key will be revealed. All other pieces of encrypted item information will not be revealed and will remain encrypted. As discussed above, theencrypted item information 112 may be re-encrypted using one of the identity-based encryption schemes to re-randomize the pieces of encrypted item information. - Referring to
FIG 5 , aprocess 500 is illustrated. Theprocess 500 may include a process for tracing an item.Process 500 may include encrypting item information using an identity-based encryption scheme with a batch number for an item as an encryption key (510) and communicating the encrypted item information for storage on an RFID tag for attachment to the item (520). - For example, the
encryption module 102 may be used to encrypt item information using an identity-based encryption scheme with a batch number for an item as an encryption key, where the batch number may be stored in the batch data 104 (510). In one exemplary implementation, the encrypted item information may include recall information (512). The recall information may include instructions to producers, distributor, end consumers, or anyone in the supply chain as to how to handle a recalled item. Instructions may include contact information such as phone number or an address regarding the recalled item or instructions on how to process the recalled item. - In one exemplary implementation, the identity-based encryption scheme may include a Boneh-Franklin scheme (514). In another exemplary implementation, the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme (516).
-
Encryption module 102 may be configured to communicate the encrypted item information for storage on anRFID tag 110 for attachment to the item (520). TheRFID tag 110 may include multiple different pieces of encrypted item information, where each of the multiple different pieces of encrypted item information is independently accessible and decryptable (522). -
Process 500 also may include re-encrypting the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information (530). For example, there-encryption module 106 may be used to re-encrypt the encrypted item information (530). In this manner, as the item information is transmitted along the supply chain, the encrypted item information is re-encrypted so that it is re-randomized. There-encryption module 106 may re-encrypt the item information without knowledge of the encryption key (e.g., the batch number) used to encrypt the item information. - In one exemplary implementation, the batch number may be communicated to a trusted third party 108 (540). A decryption key may be generated using the batch number (550). For example, the trusted
third party 108 may generate the decryption key upon proof from a particular producer that they are entitled to receive the private key using the batch number. -
Process 500 also may include issuing a recall of an item by generating a decryption key using the batch number and making the decryption key available to users of the item (560). In this manner, the decryption key is generated and is made publicly available for producers and end users along the supply chain to scan items and products using an RFID reader and a decryption key to determine whether or not an item has been recalled. Only encrypted item information on the RFID tag that matches the decryption key will be disclosed to the producer or the end user using the RFID reader. - Referring to
FIG. 6 , aprocess 600 for re-encrypting item information is illustrated.Process 600 may include receiving encrypted item information (610), re-encrypting the encrypted item information using an identity-based encryption scheme to re-randomize the encrypted item information (620) and communicating the re-encrypted item information for storage on an RFID tag for attachment to the item (630). - For example, the
re-encryption module 106 may be configured to receive the encrypted item information. There-encryption module 106 may be configured to re-encrypt the encrypted item information using one of the identity-based encryption schemes (620). In one exemplary implementation, the identity-based encryption scheme may include a Boneh-Franklin encryption scheme (622). In another exemplary implementation, the identity-based encryption scheme may include a Boneh-Boyen-Goh encryption scheme (624). Theencryption system 100 may communicate the re-encrypted item information for storage on theRFID tag 110. TheRFID tag 100 may include multiple different pieces of encrypted item information and each of the multiple different pieces of encrypted item information may be independently accessible and decryptable (632). There-encryption module 106 may be configured to re-encrypt to encrypted item information without knowledge of the encryption key (e.g., batch number) used to encrypt the item information. -
Process 600 also may include encrypting new item information using the identity-based encryption scheme with a batch number for a new item as an encryption key in communicating the encrypted new item information to the RFID tag (640). For example, theencryption module 102 may encrypt new item information using the identity-based encryption scheme with a batch number from thebatch data 104 for the new item as the encryption key. Theencryption module 102 may communicate the encrypted new item information to theRFID tag 110. In this manner, producers along the supply chain may provide their own encrypted item information as well as re-encrypting item information received from previous producers in the supply chain. That way the information from previous producers is re-randomized such that supply chain secrecy is maintained throughout the supply chain. - Referring to
FIG. 7 , an illustration is provided as to how products may be traced in the supply chain. For example,Producer X 702 may sell grain. The grain may be shipped in different batches such as batch a1704,batch a2 706, andbatch a3 708.Producer Y 710 may buy grain fromProducer X 702 and make flour out of it.Producer Y 710 also makes different batches of flour such asbatch b1 712,batch b2 714, andbatch b3 716. Note that the different batches fromProducer X 702 may contribute to a single batch of flour produced byProducer Y 710. For example,batch a3 708 is used to producebatch b3 716. However,batch a2 706 is used byProducer Y 710 to produce bothbatch b1 712 andbatch b2 714. Also,batch a1 704 is used to producebatch b1 712. -
Producer Z 718 uses the flour fromProducer Y 710 to bake bread. Just asProducer X 702 andProducer Y 710 made different batches, so too doesProducer Z 718 make multiple batches. For example,Producer Z 718 may produce multiple batches of bread includingbatch c1 720,batch c2 722, andbatch c3 724. - In one exemplary implementation, each of the producers (
Producer X 702,Producer Y 710, and Producer Z 718) may trace each of the separate batches using encrypted item information that is stored on an RFID tag. For example, each of the producers may use an ERP system such as theERP system 200 ofFIG 2 . Thebatch data 104 may store information about the produced batches and private cryptographic information used for encrypting information for each batch. To enable product tracing, each of the producers may attach 110a, 110b and 110c to their goods. The RFID tags 110a, 110b and 110c may containRFID tags 112a, 112b, and 112c. Theitem information 112a, 112b, and 112c may be encrypted using an identity-based encryption scheme. In each part of the supply chain, the producer will include encrypted item information about the batch that producer produced, and about the products and batches used in his product.item information - Referring also to
FIG. 8 ,Producer X 702 produces a good such as wheat. Instep 1, information about the batch of the goods is encrypted using an identity-based encryption scheme. The encrypted item information is written to anRFID tag 880 and sent toProducer Y 710.Producer X 702 may store the information about the batch and the private cryptographic information in thebatch data 104 of theencryption system 100 of hisERP system 200. - In
step 2,Producer Y 710 may produce a good using different batches fromProducer X 702. Each batch produced byProducer Y 710 may contain encrypted item information about the batch of the good.Producer Y 710 may use theencryption system 100 to encrypt the item information about the good produced byProducer Y 710 and to write the information to anRFID tag 885 that is sent along with the goods toProducer Z 718. TheRFID tag 885 may include the encrypted item information about the batches fromProducer Y 710 and also include the re-encrypted item information which has been re-randomized about the batches and encrypted item information that was received fromProducer X 702.Producer Y 710 may store this information in thebatch data 104 of hisencryption system 100. - Although
FIG 8 illustrates a simple example in which each batch only contains products from one other batch,FIG. 7 illustrates more complex examples in which materials from different batches may contribute to a single batch. In this instance, each of the different pieces of encrypted item information that is used to produce a single batch is re-encrypted using there-encryption module 106. - In step 3,
Producer Z 718 may produce a good and fit it with anRFID tag 890 containing encrypted information similar tostep 2. In step 4, the finished product may be shipped to a retailer that will offer the product to customers. The finished product may contain thesingle RFID tag 890 which includes the encrypted item information regarding each of the batches from each of the different producers that was used to produce the finished product. - In the food industry, samples of goods from every batch may be analyzed in a laboratory in each part of the supply chain to ensure that goods do not contain bacteria or other harmful contaminants. It is a common practice to ship the goods before having the laboratory results, since results usually arrive before the goods are used for the production status or are consumed. If there is a problem, the products may be recalled. Sometimes laboratory results arrive after goods have been used in further production steps. In this example, in
step 5,Producer Y 710 produced one batch of rotten goods. The goods were already processed byProducer Z 718 and shipped to a retailer. To enable recalling of the affected products,Producer Y 710 may reveal the private cryptographic information about the rotten batch to a trustedthird party 108. Instep 6, the trustedthird party 108 may publish this information to all retailers. The retailers can use this information to find the affected products and remove them from their shelves. - Although the examples provided illustrate encrypted item information being stored on RFID tags, other techniques might be used such as, for example, barcodes, two dimensional barcodes or holograms. In other exemplary implementations, the encrypted item information may be sent in advance, for example, using messages over a computer network. In another exemplary implementation, the encrypted item information may be sent on demand, for example, using messages over a computer network. In these examples, the encrypted item information might be exchanged using emails, web services, or remote procedure calls (RPC).
- Implementations of the various techniques described herein may be implemented in digital electronic circuitry, or in computer hardware, firmware, software, or in combinations of them. Implementations may be implemented as a computer program product, i.e., a computer program tangibly embodied in an information carrier, e.g., in a machine-readable storage device or in a propagated signal, for execution by, or to control the operation of, data processing apparatus, e.g., a programmable processor, a computer, or multiple computers. A computer program, such as the computer program(s) described above, can be written in any form of programming language, including compiled or interpreted languages, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program can be deployed to be executed on one computer or on multiple computers at one site or distributed across multiple sites and interconnected by a communication network.
- Method steps may be performed by one or more programmable processors executing a computer program to perform functions by operating on input data and generating output. Method steps also may be performed by, and an apparatus may be implemented as, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit).
- Processors suitable for the execution of a computer program include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer. Generally, a processor will receive instructions and data from a read-only memory or a random access memory or both. Elements of a computer may include at least one processor for executing instructions and one or more memory devices for storing instructions and data. Generally, a computer also may include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto-optical disks, or optical disks. Information carriers suitable for embodying computer program instructions and data include all forms of non-volatile memory, including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks, e.g., internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks. The processor and the memory may be supplemented by, or incorporated in special purpose logic circuitry.
- To provide for interaction with a user, implementations may be implemented on a computer having a display device, e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor, for displaying information to the user and a keyboard and a pointing device, e.g., a mouse or a trackball, by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including acoustic, speech, or tactile input.
- Implementations may be implemented in a computing system that includes a back-end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front-end component, e.g., a client computer having a graphical user interface or a Web browser through which a user can interact with an implementation, or any combination of such back-end, middleware, or front-end components. Components may be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a local area network (LAN) and a wide area network (WAN), e.g., the Internet.
- While certain features of the described implementations have been illustrated as described herein, many modifications, substitutions, changes and equivalents will now occur to those skilled in the art. It is, therefore, to be understood that the appended claims are intended to cover all such modifications and changes as fall within the scope of the embodiments.
Claims (15)
- A computer-implemented method for tracing an item, the method comprising:encrypting (510) item information using an identity-based encryption scheme with a batch number for an item as an encryption key; andcommunicating (520) the encrypted item information for storage on a radio frequency identification (RFID) tag for attachment to the item.
- The method as in claim 1, further comprising re-encrypting (530) the encrypted item information using the identity-based encryption scheme to re-randomize the encrypted item information.
- The method as in claim 1 or 2, wherein the encrypted item information includes (512) item recall information.
- The method as in any one of claims 1 to 3, wherein the identity-based encryption scheme includes a Boneh-Franklin (514) encryption scheme, and/or a Boneh-Boyen-Goh (516) encryption scheme.
- The method as in any one of claims 1 to 4, wherein:the RFID tag includes (522) multiple different pieces of encrypted item information; andeach of the multiple different pieces of encrypted item information is independently accessible and decryptable.
- The method as in any one of claims 1 to 5, further comprising communicating (540) the batch number to a trusted third party.
- The method as in any one of claims 1 to 6, further comprising generating (550) a decryption key using the batch number.
- The method as in any one of claims 1 to 7, further comprising issuing (560) a recall of the item by generating a decryption key using the batch number and making the decryption key available to users of the item.
- A computer-implemented method for re-encrypting item information, the method comprising:receiving (610) encrypted item information;re-encrypting (620) the encrypted item information using an identity-based encryption scheme to re-randomize the encrypted item information; andcommunicating (630) the re-encrypted item information for storage on a radio frequency identification (RFID) tag.
- The method as in claim 9, wherein the identity-based encryption scheme includes a Boneh-Franklin (622) encryption scheme, and/or a Boneh-Boyen-Goh (624) encryption scheme.
- The method as in claim 9 or 10, further comprising:encrypting (640) new item information using the identity-based encryption scheme with a batch number for a new item as an encryption key; andcommunicating the encrypted new item information to the RFTD tag.
- The method as in any one of claims 9 to 11, wherein:the RFID tag includes (632) multiple different pieces of encrypted item information; andeach of the multiple different pieces of encrypted item information is independently accessible and decryptable.
- A radio frequency identification (RFID) tag (110), comprising:a receiver module (402) that is arranged and configured to receive multiple different pieces of encrypted item information; anda storage module (404) that is arranged and configured to store the multiple different pieces of encrypted item information,wherein each of the multiple different pieces of encrypted item information is independently accessible and decryptable.
- The RFID tag (110) of claim 13, wherein each of the multiple different pieces of encrypted item information is re-encrypted using an identity-based encryption scheme to re-randomize the pieces of encrypted item information.
- A computer program product for encrypting item information, the computer program product being tangibly embodied on a computer-readable medium and including executable code that, when executed, is configured to cause at least one data processing apparatus to execute an encryption module, the encryption module configured to perform operations according to any one of claims 1 to 12.
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US12/164,589 US8060758B2 (en) | 2008-06-30 | 2008-06-30 | Item tracing with supply chain secrecy using RFID tags and an identity-based encryption scheme |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2141641A1 true EP2141641A1 (en) | 2010-01-06 |
Family
ID=41078290
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP09008546A Ceased EP2141641A1 (en) | 2008-06-30 | 2009-06-30 | Item tracing with supply chain secrecy using RFID tags and an identity-based encryption scheme |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US8060758B2 (en) |
| EP (1) | EP2141641A1 (en) |
| CN (1) | CN101650806B (en) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020215679A1 (en) * | 2019-04-25 | 2020-10-29 | 苏州车付通信息科技有限公司 | System for encrypted communication between rfid tag and reader-writer |
Families Citing this family (22)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US8320570B2 (en) * | 2008-12-05 | 2012-11-27 | Electronics And Telecommunications Research Institute | Apparatus and method for generating secret key |
| GB2469393C (en) | 2010-04-22 | 2014-08-06 | Cen Jung Tjhai | Public encryption system using deliberatily corrupted codewords from an error correcting code |
| US8745370B2 (en) * | 2010-06-28 | 2014-06-03 | Sap Ag | Secure sharing of data along supply chains |
| KR101575831B1 (en) | 2010-10-04 | 2015-12-08 | 샌디스크 세미컨덕터 (상하이) 컴퍼니, 리미티드 | Discrete component backward traceability and semiconductor device forward traceability |
| GB2473154B (en) * | 2010-11-16 | 2011-06-15 | Martin Tomlinson | Public key encryption system using error correcting codes |
| US9064229B2 (en) * | 2012-05-07 | 2015-06-23 | Sap Se | Real-time asset tracking using discovery services |
| KR20140071605A (en) * | 2012-12-04 | 2014-06-12 | 삼성전자주식회사 | Method for processing data, sensor device and user terminal |
| US9836750B2 (en) | 2013-04-24 | 2017-12-05 | Hewlett-Packard Development Company, L.P. | Validation in serialization flow |
| US9740879B2 (en) | 2014-10-29 | 2017-08-22 | Sap Se | Searchable encryption with secure and efficient updates |
| US9342707B1 (en) | 2014-11-06 | 2016-05-17 | Sap Se | Searchable encryption for infrequent queries in adjustable encrypted databases |
| CN104639543A (en) * | 2015-01-29 | 2015-05-20 | 南京三宝科技股份有限公司 | Method for checking legality of collected data of sensor based on radio frequency identification tag ID (identity) |
| US9852317B2 (en) * | 2015-07-29 | 2017-12-26 | Palo Alto Research Center Incorporated | Printable, writeable article for tracking counterfeit and diverted products |
| US9830470B2 (en) | 2015-10-09 | 2017-11-28 | Sap Se | Encrypting data for analytical web applications |
| CN105913188A (en) * | 2016-04-13 | 2016-08-31 | 苏州大成电子科技有限公司 | Multidirectional management system and multidirectional management method of RFID supply chain |
| WO2018165146A1 (en) | 2017-03-06 | 2018-09-13 | Cummins Filtration Ip, Inc. | Genuine filter recognition with filter monitoring system |
| US10963889B2 (en) | 2017-03-16 | 2021-03-30 | Sap Se | Cross-system object tracking platform |
| FR3066292B1 (en) * | 2017-05-12 | 2020-11-06 | Podvin Jean Marie | PROCESS FOR RECORDING AND STORAGE OF DATA RELATING TO FOODSTUFFS |
| CN107665414A (en) * | 2017-09-30 | 2018-02-06 | 浙江鑫泊新能源科技有限公司 | A kind of band encrypted radio-frequency identifies active digital wiring board to kinds of goods back-tracing anti-fake method |
| CN108491728A (en) * | 2018-02-01 | 2018-09-04 | 广东梦森信息科技有限公司 | Express Logistics face list information protecting method and system |
| US10746567B1 (en) | 2019-03-22 | 2020-08-18 | Sap Se | Privacy preserving smart metering |
| JP2022525991A (en) * | 2019-03-29 | 2022-05-20 | テトラ ラバル ホールディングス アンド ファイナンス エス エイ | Methods for recalling food products and their servers |
| CN110995749A (en) * | 2019-12-17 | 2020-04-10 | 北京海益同展信息科技有限公司 | Blockchain encryption method and device, electronic device and storage medium |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070206786A1 (en) | 2005-08-31 | 2007-09-06 | Skyetek, Inc. | Rfid security system |
Family Cites Families (11)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP0989497A1 (en) * | 1997-09-25 | 2000-03-29 | CANAL+ Société Anonyme | Method and apparatus for protection of recorded digital data |
| US20040200892A1 (en) * | 2003-03-07 | 2004-10-14 | Curkendall Leland D. | Method and system for anonymous trace-back of food item label claims |
| US20080001752A1 (en) * | 2005-04-21 | 2008-01-03 | Skyetek, Inc. | System and method for securing rfid tags |
| JP2007036364A (en) * | 2005-07-22 | 2007-02-08 | Nec Corp | Time device, encrypting device, decrypting device, and encrypting/decrypting system |
| US20070040682A1 (en) * | 2005-08-22 | 2007-02-22 | Mark Iv Industries Corp. | RFID inventory control system |
| US9137012B2 (en) * | 2006-02-03 | 2015-09-15 | Emc Corporation | Wireless authentication methods and apparatus |
| GB0607052D0 (en) | 2006-04-07 | 2006-05-17 | Iti Scotland Ltd | Product authentication system |
| GB2437347B (en) | 2006-04-22 | 2008-04-02 | Humberto Moran | Object tracking |
| JP5144991B2 (en) * | 2006-08-22 | 2013-02-13 | 株式会社エヌ・ティ・ティ・データ | Ciphertext decryption authority delegation system |
| CN1945591A (en) * | 2006-10-26 | 2007-04-11 | 天津市易雷电子标签科技有限公司 | Encryting anti-fake technology for electronic label |
| CN100481120C (en) * | 2007-04-23 | 2009-04-22 | 中国振华(集团)科技股份有限公司 | Production RFID false proof method with logic control unit |
-
2008
- 2008-06-30 US US12/164,589 patent/US8060758B2/en active Active
-
2009
- 2009-06-30 CN CN2009101669712A patent/CN101650806B/en active Active
- 2009-06-30 EP EP09008546A patent/EP2141641A1/en not_active Ceased
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070206786A1 (en) | 2005-08-31 | 2007-09-06 | Skyetek, Inc. | Rfid security system |
Non-Patent Citations (6)
| Title |
|---|
| CHIU C TAN ET AL: "A Robust and Secure RFID-Based Pedigree System (Short Paper)", 1 January 2006, INFORMATION AND COMMUNICATIONS SECURITY LECTURE NOTES IN COMPUTER SCIENCE;;LNCS, SPRINGER, BERLIN, DE, PAGE(S) 21 - 29, ISBN: 978-3-540-49496-6, XP019051576 * |
| G. ATENIESE, J. CAMENISCH, B. DE MEDEIROS: "Untraceable RFID tags via insubvertible encryption", PROCEEDINGS OF THE 12TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY 2005, November 2005 (2005-11-01), ACM, New York, NY, USA, pages 92 - 101, XP002547789, ISBN: 1-59593-226-7 * |
| G. ATENIESE; J.CAMENISCH; B. DE MEDEIROS, UNTRACEABLE RFID TAGS VIA INSUBVERTIBLE ENCRYPTION |
| JUNICHIRO SAITO, JAE-CHEOL RYOU, KOUICHI SAKURAI: "Enhancing Privacy of Universal Re-encryption Scheme for RFID Tags", LECTURE NOTES IN COMPUTER SCIENCE, EMBEDDED AND UBIQUITOUS COMPUTING, vol. 3207, 30 July 2004 (2004-07-30), Springer Berlin / Heidelberg, pages 879 - 890, XP002547790, ISBN: 978-3-540-22906-3 * |
| YAN LIANG ET AL: "RFID System Security Using Identity-Based Cryptography", UBIQUITOUS INTELLIGENCE AND COMPUTING; [LECTURE NOTES IN COMPUTER SCIENCE], SPRINGER BERLIN HEIDELBERG, BERLIN, HEIDELBERG, vol. 5061, 23 June 2008 (2008-06-23), pages 482 - 489, XP019090250, ISBN: 978-3-540-69292-8 * |
| YAN LIANG, RFID SYSTEM SECURITY USING IDENTITY-BASED CRYPTOGRAPHY |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2020215679A1 (en) * | 2019-04-25 | 2020-10-29 | 苏州车付通信息科技有限公司 | System for encrypted communication between rfid tag and reader-writer |
Also Published As
| Publication number | Publication date |
|---|---|
| US20090323928A1 (en) | 2009-12-31 |
| US8060758B2 (en) | 2011-11-15 |
| CN101650806A (en) | 2010-02-17 |
| CN101650806B (en) | 2013-08-14 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US8060758B2 (en) | Item tracing with supply chain secrecy using RFID tags and an identity-based encryption scheme | |
| US9159046B2 (en) | Systems and methods for implementing supply chain visibility policies | |
| US8811620B2 (en) | Secure sharing of item level data in the cloud | |
| EP2544425B1 (en) | Secure dissemination of events in a publish/subscribe network | |
| US8756410B2 (en) | Polynomial evaluation delegation | |
| US20130329889A1 (en) | System and method for providing secure product data collection, monitoring, and tracking | |
| JP2018513597A (en) | Method and apparatus for providing a universal, deterministic reproducible representation of cryptographic key pairs for all SKUs, shipping cartons and items | |
| US20160358264A1 (en) | Equity income index construction transformation system, method and computer program product | |
| CN110390212B (en) | Supply monitoring method based on block chain and node device | |
| JP5137046B1 (en) | Series data protection method and series data protection program | |
| Dixit | The impact of quantum supremacy on cryptography: Implications for secure financial transactions | |
| US20070174196A1 (en) | System and method for verifying authenticity | |
| US11687878B2 (en) | Privacy-preserving supply chain verification for multiple asset types in shared data storage scenarios | |
| CN101521670B (en) | Method and system for acquiring application data | |
| US20230080637A1 (en) | System and method for executing data access transaction | |
| Kumbhakar et al. | CTEA: Chaos based tiny encryption algorithm using ECDH and TinkerBell map for data security in supply chain management | |
| CN114943038B (en) | Query method, server, query system, computer device and storage medium | |
| EP4156072A1 (en) | Transaction tracing method and apparatus based on blockchain | |
| Han et al. | Fine-grained business data confidentiality control in cross-organizational tracking | |
| JP2017129644A (en) | Secret calculation information exchange system, data processing apparatus, secret calculation information exchange method, secret calculation information exchange program, and recording medium | |
| CN110210975A (en) | Data trade method and its equipment on block chain | |
| Kumar et al. | DEBPIR: enhancing information privacy in decentralized business modeling | |
| Karthika | IoT sensors: security in network forensics | |
| CN115544544B (en) | Data incentive methods, data incentive devices, electronic devices and storage media | |
| Lee et al. | A New Privacy-preserving Path Authentication Scheme using RFID for Supply Chain Management. |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO SE SI SK TR |
|
| 17P | Request for examination filed |
Effective date: 20100204 |
|
| 17Q | First examination report despatched |
Effective date: 20100719 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20120524 |
